How to Verify Supplier Bank Details Before Paying an Invoice
Invoice redirection fraud cost Australian businesses $79.4M last year. The ACCC and AFP agree it's the #1 business fraud type. Here are the five checks that stop it — and how to run them in under two minutes.
The request landed at 9:42 a.m. on a Tuesday. Perfect timing — smack in the middle of an end-of-month payment run, when fatigue is louder than caution.
The email was from a long-standing supplier, a building materials company the business had dealt with for seven years. The sender's name matched the accounts receivable contact in the accounting system. The logo sat cleanly in the signature block. The tone was friendly, professional, unhurried. They apologised for the inconvenience, explained they were consolidating their banking arrangements, and attached a crisp PDF on what looked like company letterhead with new account details. The BSB was with one of the major banks. The account name matched the trading name exactly.
The accounts payable officer had forty-seven invoices to process before noon. She read the request, cross-referenced the outstanding balance, and updated the supplier record. The payment of $86,340 was queued for the afternoon batch and released on schedule.
The real supplier called three weeks later, wondering why their invoice hadn't been paid.
The email address, examined after the fact, showed an extra character — a lowercase L replaced with an uppercase I in the domain. The PDF letterhead had been lifted from a real document months earlier, when the supplier's own email account was compromised. The BSB belonged to a mule account at the same bank, purchased by a syndicate weeks before. By the time the fraud team was involved, the funds had been splintered across twelve accounts and withdrawn as cryptocurrency.
The business took a direct $86,000 hit. Not covered by cyber insurance, which required verbal confirmation of any banking change — a clause nobody remembered reading.
Why Invoice Redirection Fraud Is Surging in Australia
If that scenario feels like an edge case, the numbers say otherwise. Business email compromise (BEC) — invoice redirection, CEO impersonation, and supplier email takeover — is now the most damaging white-collar crime targeting Australian organisations. The ACCC's ScamWatch platform logged $79.4 million in reported losses to BEC in 2023 alone, up from $24.6 million in 2021. Many losses go unreported; the true figure is substantially higher.
The Australian Federal Police has been direct about the trend. Operation Dolos, the AFP-led taskforce targeting BEC syndicates, identifies invoice redirection as the number one fraud type by both frequency and financial impact for Australian businesses. In one six-month window the AFP attributed over $36 million in losses to this single method alone.
The syndicates are organised, transnational, and patient. They compromise a legitimate email account — often through spear-phishing or a credential leak — then wait. They read invoices. They study payment cycles. They learn the tone of the relationship and the precise moment the next payment is due. Only then do they strike, inserting themselves into an existing conversation with a request that looks exactly like business as usual.
The cost of a single oversight
The Australian Signals Directorate's Cyber Threat Report 2023 highlighted one Australian business that lost $2.3 million across five redirected payments before the fraud was detected. The attackers had been monitoring the email account for eleven months before making their first move. Every case in the ASD's sample involved a failure to verify the new bank details through an independent channel.
Source: ASD Cyber Threat Report 2022–2023
Five Checks Before Updating Bank Details
Verifying supplier bank details is not a one-step process. No single check is reliable on its own, because attackers anticipate each individual verification that depends on the email itself. Here is the five-step check that should sit between any bank change request and the decision to update payment records.
1. Verify the domain and email authenticity
Attackers register look-alike domains or compromise real accounts. Look-alike domains use character substitution — 'rn' instead of 'm', a Cyrillic 'a' indistinguishable from a Latin one — to pass a visual scan. Pull the sender's domain, compare it against the supplier's genuine domain on your records or their website at rest (not a link in the email), and confirm character for character. Then examine whether the email passed authentication checks. A failed DMARC check is a red flag sufficient to halt the process entirely.
Related: What is DMARC and why it protects your payments →
2. ABN register check
Every legitimate Australian business has an Australian Business Number. Pull the ABN from your own system — not from the email — and verify on the public register that the entity is still active. This confirms the supplier is who you understood them to be, and often surfaces the registered business address, useful for cross-referencing in the next step.
3. Phone call to the ABR-registered number — not the one in the email
This is the non-negotiable step. You must speak to a person at the supplier's organisation who can confirm the bank change verbally. And you must source the phone number independently. Never use a number in the change request email, the attached PDF, or the email signature. Attackers provide their own numbers and have someone waiting.
The correct source is the genuine number you already have on file, or the publicly listed number associated with the supplier's ABR-registered address. If you cannot independently locate a trusted phone number, the verification fails and the bank details should not be changed.
4. BSB validation
A BSB lookup reveals the bank and branch location. If a long-standing Queensland supplier suddenly asks you to pay into a Western Australian branch of a bank they've never used, that disparity warrants independent questioning. BSB and account number combinations can also be validated for structural correctness and checked against known risk indicators.
Related: BSB validation explained →
5. DMARC check on the sender's domain
DMARC tells receiving mail servers how to handle emails that fail authentication. A domain with DMARC set to 'reject' is far harder to impersonate. A domain with no DMARC record offers no such protection — and a supplier with no DMARC record is more likely to have had their own accounts compromised.
Why the phone call is the step most businesses skip
A 2024 survey of 300 Australian mid-market finance teams found 61% sometimes or regularly update supplier payment details based on emailed requests alone when the request appears to come from a known contact. Most common reasons: existing supplier relationship (misplaced trust), volume pressure during payment runs, the email address "looked right," and no alternative phone number readily available.
Attackers design their approach precisely to exploit these conditions.
How Gumshoe Bank-Change Check Automates All Five
Running five checks for every bank change request is the gold standard. In practice, accounts teams face a collision between ideals and time. The person processing forty supplier records a day cannot manually run ABR lookups, BSB validations, DMARC checks, and outbound verification calls for each one. They default to what is achievable, and the achievable is often a surface-level glance.
Gumshoe's Bank-Change Check executes all five checks automatically and returns a complete verification report without the finance team needing to leave their workflow.
- Voice Verify calls the ABR-registered number — Gumshoe cross-references the supplier's ABN against directory data to surface an externally sourced phone number, then places a recorded call asking the recipient to confirm the bank change. The number is never sourced from the email — this stops the attacker's most common end-run.
- Places cross-references the phone — The Places engine takes the business address from the ABR, matches it against public directory listings, and surfaces a verified phone number associated with that physical location.
- BSB validated — The submitted BSB is validated against the Australian Payments Network directory. Branch location inconsistencies are flagged.
- DMARC checked — The sender's domain DMARC configuration is retrieved and reported alongside the other checks.
The output is a structured, timestamped report. If the payment is later questioned by an insurer or auditor, the business can demonstrate it took reasonable, documented, multi-step verification — not a single emailed confirmation.
Insurance and audit requirements are tightening
Cyber insurers in the Australian market are increasingly mandating multi-factor verification for supplier bank changes as a condition of coverage. One major insurer's 2025 policy wording now requires "verbal confirmation via an independently sourced telephone number" for any payment detail change above $5,000. Claims where this step was not followed are being denied. A platform-generated report with call recordings and timestamps meets this threshold without adding procedural drag.
What to Do When You Cannot Reach Them
Reality is messier than the ideal. Suppliers are often sole traders on the road, small teams in different time zones, or businesses where the one person who handles accounts also runs operations and rarely answers an unknown number first ring.
Gumshoe's Voice Verify handles this with three layers of fallback:
- Voicemail detection — When the automated call reaches voicemail, the system detects the greeting pattern and logs a WARN result. The finance team sees this clearly: a person was not reached.
- Retry scheduling — Three attempts are made across 24–48 hours, spread across morning, midday, and late afternoon windows to maximise the chance of reaching someone. Opening hours from Google Places are used to avoid calling when the business is closed.
- Credit for unresolvable attempts — If three attempts fail to reach a human, the verification closes as "unresolvable" and the credit never expires. You pay for certainty, not busy signals.
Related: Full Voice Verify guide →
The Five-Point Verification Checklist
Before processing the next supplier bank change request, run this sequence. Keep it in your payment approval workflow.
- Domain inspection — Check the sender's email domain character by character against your supplier record and their genuine website. Look for substitutions (rn/m, I/l, 0/o).
- ABN register check — Verify the supplier's ABN on the Australian Business Register using the ABN from your own records, not the email.
- Independent phone verification — Call a number you sourced independently from the email — registered address, your existing records, or a verified directory listing. Do not use any number from the change request.
- BSB lookup — Validate the BSB against the Australian Payments Network directory. Flag any inconsistency with the supplier's known banking location.
- DMARC check — Look up the DMARC record for the sender's domain. A missing or 'none' policy is a warning sign, not a block, but it belongs in your risk picture.
Or: run all five at once at gumshoe.au. One search. Two minutes. A report you can archive.